Security

After upgrading from 6.3.7 to 6.5.2, why are we getting the error on search: "Cannot get username when all users are selected"?

jamesoconnell
Path Finder

After upgrading from 6.3.7 to 6.5.2, we are getting the error on search: "Cannot get username when all users are selected".

Some people are getting this and some aren't.
We are also seeing different results for different browsers relative this error.

Regards.

1 Solution

jamesoconnell
Path Finder

Thanks for the response.

A colleague recommended deleting browser history to 'end of time' -- which worked.

Regards.

View solution in original post

jamesoconnell
Path Finder

Thanks for the response.

A colleague recommended deleting browser history to 'end of time' -- which worked.

Regards.

jcrabb_splunk
Splunk Employee
Splunk Employee

Well that is certainly a simple fix. I appreciate you following up for others that may run into this as well.

Jacob
Sr. Technical Support Engineer
0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

I had a customer run into this when going to 6.3.0 and it was resolved in 6.3.2:

http://docs.splunk.com/Documentation/Splunk/6.3.2/ReleaseNotes/6.3.2#Upgrade_issues

  • SPL-107449: After upgrade to 6.3 some Splunk web elements are missing due to cookie arrays failing to be parsed.

I realize you are on a newer version but just for context (or other folks who have this error), I wanted to include that. Also, looking at this bug, there were some customers who had this error but it was due to other issues:

  • Issue occurred upgrading from 6.3.x to 6.4. Customer corrected by disabling sticky persistent session in F5, just turned it off. the persistence profile of load balancer was misconfigured.

  • They had NFS storage and there was a time issue: The NFS storage software was set to a different timezone than the server that was utilizing it. Although the date/time matched, the time zone was different. While investigating the web_service.log we noted many "Session expired" messages. Time drift on the NFS was heavily interfering with Splunk web. Correcting the time zone on the NFS fixed the issue. ** Just a further note, as we've just gone through Daylight Savings time here in most of the US, this could be a likely candidate or something else related to time skew and storage.

Jacob
Sr. Technical Support Engineer
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...